CVE-2026-2203Disclosure(tenda / ac8)

LOWCVSS 7.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch tenda ac8 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /goform/fast_setting_wifi_set of the component Embedded Httpd Service. This manipulation of the argument timeZone causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ac8
  • ac8_firmware

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-09)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ac8ac8_firmware

2 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-08: 1Mentions · 2026-02-09: 2Patch / Workaround · 2026-02-09: 1Technical Details · 2026-02-09: 202-0802-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-081
Disclosure1
2026-02-092
Disclosure2
Full discourse3 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2203: HIGH] Vulnerability discovered in Tenda AC8 16.03.33.05 allows buffer overflow via timeZone parameter manipulation in /goform/fast_setting_wifi_set. Remote attacks are a risk.#cve,CVE-2026-2203,#cybersecurity https://cvefind.com/CVE-2026-2203

    Post summary

    The post announces a high‑severity buffer overflow in Tenda AC8’s Wi‑Fi settings, triggered by manipulating the timeZone parameter, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0000087
    583 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 HIGH severity! CVE-2026-2203: Buffer overflow in Tenda AC8 routers (FW 16.03.33.05) lets remote attackers gain control via /goform/fast_setting_wifi_set. Patch ASAP & monitor HTTP traffic. Details: https://radar.offseq.com/threat/cve-2026-2203-buffer-overflow-in-tenda-ac8-23... https://t.co/sb4Z2jl8Uw

    Post summary

    CVE‑2026‑2203 is a high‑severity buffer‑overflow flaw in Tenda AC8 routers that permits remote attackers to gain full control through the /goform/fast_setting_wifi_set endpoint; patches are urgently required and traffic should be monitored.

    0000061
    268 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Tenda AC8 (CVE-2026-2203) https://vuldb.com/?id.344906

    Post summary

    A new critical vulnerability (CVE-2026-2203) has been disclosed for the Tenda AC8, with no additional technical details or mitigation information provided.

    0000091
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtendaac8---
OStendaac8_firmware16.03.33.05--

Explore more